CISM Exam QuestionsBrowse all questions from this exam

CISM Exam - Question 453


An information security policy was amended recently to support an organization's new information security strategy. Which of the following should be the information security manager's NEXT step?

Show Answer
Correct Answer: B

Once the information security policy has been amended to support a new information security strategy, the next logical step for the information security manager is to update the relevant standards and procedures. These standards and procedures provide detailed guidance on how to implement the policies day-to-day and ensure that the strategy is effectively put into practice across the organization. Without updated standards and procedures, the amended policy may not be consistently followed or effectively enforced.

Discussion

11 comments
Sign in to comment
CarlLimpsOption: B
Feb 14, 2023

I like B because evaulating to the business strategy should have been done already.

aokisanOption: A
Dec 20, 2022

need to evaluate to business strategy.

kortclOption: B
Apr 28, 2023

I agree, the answer should be B. The business strategy alignment would've already been completed.

oluchecpointOption: A
Sep 7, 2023

A. Evaluate the alignment with business strategy Before making any further changes or updates, it's essential to ensure that the recently amended information security policy aligns with the organization's new information security strategy and, more importantly, with the overall business strategy. This alignment ensures that information security efforts are in sync with the organization's goals and objectives. Once alignment is confirmed, the information security manager can proceed with other tasks.

oluchecpoint
Feb 6, 2024

changing to answer B

welloOption: B
Jun 10, 2023

Information security strategy is already aligned to business, so no need to realign. B. Update standards and procedures

richck102Option: B
Jun 28, 2023

B. Update standards and procedures

GoseuOption: B
Jul 14, 2023

Β is the best answer .

Jess20Option: B
Dec 1, 2023

B. Update standards and procedures A was done already

oluchecpointOption: B
Feb 6, 2024

B. Update standards and procedures

yottabyteOption: C
Mar 26, 2024

Wouldn't you review the technical controls first and then amend the standards and policies based on the requirements of technical controls. For example: if the new regulation dictates that all banks online portal access requires a 12 digit alpha numeric password and if you are updating the standard and guidelines only to find out your control is not capable of accommodating more than 10 characters, you will do a control upgrade and then update the standard and guidelines, is that correct?

e891cd1Option: A
Jul 11, 2024

I would go with A..The question specifically said the strategy is NEW..if it is a new strategy then it needs to be align with the business..